Amazon Linux 2.0.202200419.0 release notes - Amazon Linux 2

Amazon Linux 2.0.202200419.0 release notes

Amazon Linux 2 was updated.

Package updates

Amazon Linux 2 includes the following packages.

Packages

kernel-4.14.275-207.503.amzn2.aarch64

kernel-4.14.275-207.503.amzn2.x86_64

kernel-5.10.109-104.500.amzn2.aarch64

kernel-5.10.109-104.500.amzn2.x86_64

kernel-devel-4.14.275-207.503.amzn2.x86_64

kernel-headers-4.14.275-207.503.amzn2.x86_64

kernel-tools-4.14.275-207.503.amzn2.aarch64

kernel-tools-4.14.275-207.503.amzn2.x86_64

kernel-tools-5.10.109-104.500.amzn2.aarch64

kernel-tools-5.10.109-104.500.amzn2.x86_64

libblkid-2.30.2-2.amzn2.0.7.aarch64

libblkid-2.30.2-2.amzn2.0.7.x86_64

libcap-2.54-1.amzn2.0.1.aarch64

libcap-2.54-1.amzn2.0.1.x86_64

libfdisk-2.30.2-2.amzn2.0.7.aarch64

libfdisk-2.30.2-2.amzn2.0.7.x86_64

libmount-2.30.2-2.amzn2.0.7.aarch64

libmount-2.30.2-2.amzn2.0.7.x86_64

libsmartcols-2.30.2-2.amzn2.0.7.aarch64

libsmartcols-2.30.2-2.amzn2.0.7.x86_64

libuuid-2.30.2-2.amzn2.0.7.aarch64

libuuid-2.30.2-2.amzn2.0.7.x86_64

util-linux-2.30.2-2.amzn2.0.7.aarch64

util-linux-2.30.2-2.amzn2.0.7.x86_64

Kernel updates

Rebase kernel to upstream stable 4.14.275

CVEs fixed:

  • CVE-2022-26490 [nfc: st21nfca: Fix potential buffer overflows in EVT_TRANSACTION]

  • CVE-2022-27666 [esp: Fix possible buffer overflow in ESP transformation]

  • CVE-2022-28356 [llc: fix netdevice reference leaks in llc_ui_bind()]

Amazon Features and Backports:

  • Revert "not-for-upstream: kernel/sys: Fake stable version for microvm kernel"

  • not-for-upstream: Makefile: Fake stable version for microvm kernel

  • bpf: Verifer, adjust_scalar_min_max_vals to always call update_reg_bounds()

  • Enable CONFIG_CHECKPOINT_RESTORE in aarch64

Rebase kernel to upstream stable 5.10.109

CVEs fixed:

  • CVE-2022-27666 [esp: Fix possible buffer overflow in ESP transformation]

  • CVE-2022-1048 [ALSA: pcm: Fix races among concurrent hw_params and hw_free calls]

  • CVE-2022-26490 [nfc: st21nfca: Fix potential buffer overflows in EVT_TRANSACTION]

  • CVE-2022-28356 [llc: fix netdevice reference leaks in llc_ui_bind()]

Amazon Features and Backports:

  • Enable CONFIG_CHECKPOINT_RESTORE in aarch64